Forum Discussion
Exclude Devices from Secure Score
DFE provides an "Exclude" option and this can be applied to multiple devices using the filters. Once excluded, these devices no longer affect the Secure Score and are hidden from vulnerability Management dashboard as well
- Stewart-MSep 26, 2025Copper Contributor
Thanks for the response.
I have just tried and unfortunately, I can only do up to 5 devices at a time in Device Inventory. I need to exclude all future hosts with a hostname prefix and current ones, there are several thousands of devices needing excluded as new ones are frequently spun up and torn down during testing.
All these devices are in a Defender Dynamic Device Group which is populated so is there a way to exclude with this device group?
- muraly005Sep 28, 2025Copper Contributor
There is another option where you can exclude the devices from being discovered but that is based on IP address ranges, if these devices set with the particular IP address range, then this will be a suitable option.
https://learn.microsoft.com/en-us/defender-endpoint/device-discovery-faq#how-can-i-exclude-targets-from-being-probed-with-standard-discovery